Tag: Versa Director Vulnerability

CISA Urges Federal Agencies to Patch Versa Director Vulnerability by September
News

CISA Urges Federal Agencies to Patch Versa Director Vulnerability by September

Based on proof of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Versa Director security issue to its list of known exploited vulnerabilities (KEVs). A file upload problem affecting the "Change Favicon" feature is the source of the medium-severity vulnerability, identified as CVE-2024-39717 (CVSS score: 6.6). This exploit could enable a threat actor to submit a malicious file by disguising it as a seemingly innocent PNG image file. According to a CISA alert, administrators with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin access can alter the user interface of the Versa Director GUI through an unlimited upload of files with a hazardous type vulnerability read more about CISA Urges Federal Agencies to Patch Versa D...